Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in
Locally is a set of services listening on your machine, reached through *.locally hostnames that its own DNS server answers. This page is the complete port map, which listeners are reachable from beyond the loopback interface, how containers find their way back to Locally, and what to do when a proxy, VPN or corporate resolver sits in the way.
Locally uses 5660-5680 plus 5671 and 5883. Every listener binds 127.0.0.1 unless the Bind column says otherwise.
| Port | Service | Bind | Mode |
|---|---|---|---|
| 5660 | Storage Emulator (Blob, File, Queue, Table, DFS) | loopback | both |
| 5661 | Key Vault Emulator (vaults and Managed HSM) | loopback | both |
| 5662 | Service Bus, Event Hubs, Event Grid and IoT Hub over HTTPS | loopback | both |
| 5663 | Web Apps, Function Apps and Container Apps | loopback | both |
| 5664 | App Configuration Emulator | loopback | both |
| 5665 | Cosmos DB Emulator (NoSQL) | loopback | both |
| 5666 | Cosmos DB Emulator (MongoDB wire protocol) | loopback | both |
| 5667 | Container Registry Emulator | loopback | both |
| 5668 | Application Insights and Log Analytics ingestion and query | loopback | both |
| 5669 | Container gateway - the door containers and database clients come in through: Container Instances, Virtual Machine endpoints, and the Postgres, MySQL, SQL Server and Redis entry listeners | loopback | both |
| 5671 | Service Bus and Event Hubs over AMQP | loopback | both |
| 5673 | DNS server, UDP and TCP | all interfaces | both |
| 53 | The DNS server again, for the Windows NRPT rule (which cannot name a port). Best-effort: if another resolver holds :53 Locally still starts. | 127.0.0.1:53 | Windows |
| 5674 | CI Automation API | loopback | locally ci |
| 5675 | Locally's state store (internal) | loopback | both |
| 5676 | HTTP request/response logging | loopback | locally build |
| 5677 | Authorization - OAuth2/OIDC token endpoint and sign-in pages | loopback | both |
| 5678 | Locally Dashboard | loopback | locally build |
| 5679 | Directory (Entra) and Microsoft Graph | loopback | both |
| 5680 | Control Plane - the Resource Manager API | loopback | both |
| 5883 | Event Hubs and IoT Hub over MQTT | loopback | both |
| random | Managed-identity token endpoint for hosted apps (the App Service IDENTITY_ENDPOINT protocol). Bound to all interfaces so a container can reach it through the host gateway; every request must carry the per-app secret header, and the port is chosen at launch. | all interfaces | both |
Plugins (one process per installed Resource Provider) are handed their listener by Locally - an inherited socket on macOS and Linux, a loopback port Locally allocates at launch on Windows - so they never need a port of their own in the map. Mode both means locally build and locally ci. The external endpoints Locally calls are listed in Security & Telemetry.
Two listeners bind every interface, and both are there so that containers - which reach the host through a gateway address, not loopback - can use them: the DNS server on 5673, and the managed-identity endpoint above. Neither hands out anything without a credential: DNS answers only for names that exist, and the identity endpoint refuses requests without the secret Locally injects into the app it belongs to. Everything else, including the control plane and every data plane, is loopback-only; there is no flag to expose them, and a teammate cannot point their tools at your Locally. A firewall that blocks inbound 5673/udp and 5673/tcp from the LAN costs you nothing unless you run containers in a VM (see below).
Inside a container, 127.0.0.1 is the container, and a *.locally name has to resolve to the host instead. How that happens depends on where the container runtime lives:
.locally rule from locally configure dns already applies. Nothing to do.locally configure podman writes a rule into that VM forwarding the whole .locally domain to Locally's DNS server on the host and rewriting loopback answers to the VM's host address, and installs the local CA in the VM's trust store so the daemon can push to and pull from the registry emulator.locally build starts a small DNS forwarder container on Docker's network once the DNS server is up, and every container Locally launches is pointed at it with --dns. Your own containers and the daemon itself are untouched, which is why docker push to the registry emulator stays a Podman-only capability today.
Every container Locally launches is also given the local CA, so Azure SDK calls from inside a Web App or Function App to Storage, Key Vault or the control plane verify without changes. In the other direction, the container gateway on port 5669 is how you reach a container: each container group and VM endpoint is published under a <name>.gondola.locally hostname, which is what az container show hands back as an address that actually responds.
If your shell exports HTTPS_PROXY or HTTP_PROXY, the Azure CLI, Terraform and the SDKs will send Locally traffic to that proxy, which cannot reach 127.0.0.1 on your machine and doesn't trust Locally's CA. locally run passes your proxy variables through untouched, so exclude Locally explicitly:
$
export NO_PROXY="${NO_PROXY:+$NO_PROXY,}.locally,localhost,127.0.0.1"
Set no_proxy as well if a tool only reads the lower-case form (curl and some Python versions). Locally's own outbound calls - certificate renewal, sign-in, updates - honour the same proxy variables, so a proxy that is required for internet access is fine as long as *.locally.build is allowed through it.
locally configure dns adds a resolver rule for the .locally domain only (an /etc/resolver/locally file on macOS, a systemd-resolved drop-in on Linux, an NRPT rule on Windows); every other lookup keeps going to your normal DNS. Some VPN clients rewrite the resolver configuration when they connect and put it back when they disconnect, which can drop the rule while the tunnel is up. If *.locally stops resolving after connecting:
$
locally configure dns --status
reports whether the rule is still present, and re-running locally configure dns restores it without touching anything else. A resolver that answers NXDOMAIN for a Storage Account you just created is usually Locally telling the truth - see DNS Server on why only resources that exist resolve.
Locally cannot share its ports with another process. When a launch fails with a bind error naming one of the addresses above, find the holder (lsof -i :5680 on macOS and Linux, netstat -ano | findstr 5680 on Windows); the usual culprits are a second Locally instance or a service a crashed launch didn't get to stop. On Windows, port 53 is shared with any other local resolver; Locally treats it as best-effort and still starts on 5673 when it can't bind 53, but the NRPT rule then has nowhere to send queries until the other resolver is stopped.
Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in
Your Azure infrastructure, running on your machine. Deploy in seconds, break things freely, and ship to Azure when you're ready.